Light

Episode #947 Quiz

Article 45
Date: 2023-11-07 | Length: 2 hrs | Episode page at twit.tv

About this episode

Microsoft is moving Azure signing keys into hardened HSMs and confidential computing, with encrypted-at-rest/in-transit/process and automated rotation. Trend Micro disclosed four Exchange zero-days, including unauthenticated deserialization RCE and URI-based information disclosure, but Microsoft deferred fixes. ActiveMQ and Citrix Bleed showed exploitation, credential theft, persistence, and mass compromise patterns.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode, what did Microsoft say it was moving into its integrated hardened Azure HSM and confidential computing infrastructure as part of the Secure Future Initiative?
Question 2: Why did Trend Micro's Zero-Day Initiative publish rough descriptions and locations for four Exchange Server zero-days after Microsoft declined to fix them immediately?
Question 3: What was the key reason Mandiant said it was difficult to investigate the Citrix NetScaler exploitation?
Question 4: What sequence of tools did Mandiant say attackers used to stage and exfiltrate reconnaissance results after Citrix session hijacking?
Question 5: What specific ability did the proposed Article 45 give to EU member states and recognized third-party countries regarding browser trust?
Cancel